Martijn Wargers and Nick Mott discovered a vulnerability when
rendering malformed JavaScript content. The Mozilla Firefox 1.0 line is
not affected.

Impact

If JavaScript is enabled, by tricking a user into visiting a
malicious web page which would send a specially crafted HTML script
that contains references to deleted objects with the "designMode"
property enabled, an attacker can crash the web browser and in theory
manage to execute arbitrary code with the rights of the user running
the browser.